From 8cc6c8b851693155e49126b12b65cb8eaa9ef3e3 Mon Sep 17 00:00:00 2001 From: Alex English Date: Sun, 2 Mar 2025 07:32:21 -0800 Subject: [PATCH 01/12] push image to incubator --- .github/workflows/deploy-to-incubator.yml | 60 ++++++++++------------- 1 file changed, 25 insertions(+), 35 deletions(-) diff --git a/.github/workflows/deploy-to-incubator.yml b/.github/workflows/deploy-to-incubator.yml index ef72c3892..776148a8f 100644 --- a/.github/workflows/deploy-to-incubator.yml +++ b/.github/workflows/deploy-to-incubator.yml @@ -6,9 +6,7 @@ on: type: choice description: The AWS environment to deploy (dev/test/prod) options: - - dev - - test - - prod + - qa permissions: id-token: write contents: read @@ -18,43 +16,35 @@ jobs: steps: - name: Clone repo uses: actions/checkout@v4 + - name: Configure aws credentials uses: aws-actions/configure-aws-credentials@v4 with: - role-to-assume: arn:aws:iam::035866691871:role/gha-incubator - role-session-name: ghaincubatorsession + role-to-assume: arn:aws:iam::035866691871:role/incubator-cicd-home-unite-us + role-session-name: incubator-cicd-people-depot aws-region: us-west-2 - - name: Push Docker container to ECR - # env: - # IMAGE_URL: ${{ }} - run: | - docker push - - name: Update ECS - # env: - # IMAGE_URL: ${{ }} - run: | - ## TODO: this will free us from having to maintain the template ecs task defintion - ## file in sync with its terraform equivalent in the incubator IAC repo - # aws ecs describe-task-definition --task-definition homeuniteus --output json \ - # | jq --arg IMAGE_URL "${IMAGE_URL}" '.taskDefinition | .containerDefinitions[0].image = $IMAGE_URL' \ - # > ./ecs-task-definition.json - - # populate and load the template file, by replacing the templated value(s) and storing output in a - # local env var - ECS_TASK_DEFINITION=$( sed "s/__IMAGE_URL__/${IMAGE_URL}/g" < ./.incubator/ecs-taskdef-template.json ) - - # register the task definition with the updated docker image url, write output to both stdout and - # local json file - aws ecs register-task-definition --cli-input-json "${ECS_TASK_DEFINITION}" \ - | tee ./ecs-taskdef-revision.json - - # force a new deployment for the new task definition we just registered - aws ecs update-service \ - --cluster incubator-prod \ - --service homeuniteus \ - --task-definiton homeuniteus \ - --force-new-deployment + - name: Login to Amazon ECR + id: login-ecr + uses: aws-actions/amazon-ecr-login@v1 + + - name: Build, tag, and push the image to Amazon ECR + id: build-push-image + env: + ECR_REGISTRY: ${{ steps.login-ecr.outputs.registry }} + ECR_REPOSITORY: home-unite-us-fullstack + IMAGE_TAG: ${{ inputs.target-host-environment }} + run: | + docker build -f ./.incubator/app.Dockerfile -t $ECR_REGISTRY/$ECR_REPOSITORY:$IMAGE_TAG . + docker push $ECR_REGISTRY/$ECR_REPOSITORY:$IMAGE_TAG + + # - name: Redeploy image in ECS + # id: redeploy-service + # env: + # CLUSTER_NAME: incubator-prod + # SERVICE_NAME: home-unite-us-fullstack-${{ inputs.target-host-environment }} + # run: | + # aws ecs update-service --force-new-deployment --service $SERVICE_NAME --cluster $CLUSTER_NAME From 204d4d663d88a50dff68dffd31b7cb89946e2548 Mon Sep 17 00:00:00 2001 From: Alex English Date: Sun, 2 Mar 2025 07:35:09 -0800 Subject: [PATCH 02/12] fix repo name --- .incubator/app.Dockerfile | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/.incubator/app.Dockerfile b/.incubator/app.Dockerfile index 0a6076fda..31146ba44 100644 --- a/.incubator/app.Dockerfile +++ b/.incubator/app.Dockerfile @@ -1,6 +1,6 @@ ARG NODE_VERSION=20.18.0-bookworm ARG HUU_BASE_VERSION=1.1 -ARG HUU_ECR_REPOSITORY=035866691871.dkr.ecr.us-west-2.amazonaws.com/homeuniteus +ARG HUU_ECR_REPOSITORY=035866691871.dkr.ecr.us-west-2.amazonaws.com/home-unite-us-fullstack # use the official Node image for building the UI bundle FROM node:${NODE_VERSION} AS client-builder From e28f82114f358e4c1fcccb9e0fb867a275b3d0b8 Mon Sep 17 00:00:00 2001 From: Alex English Date: Sun, 2 Mar 2025 07:35:50 -0800 Subject: [PATCH 03/12] fix job name --- .github/workflows/deploy-to-incubator.yml | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/.github/workflows/deploy-to-incubator.yml b/.github/workflows/deploy-to-incubator.yml index 776148a8f..ed9b19ef5 100644 --- a/.github/workflows/deploy-to-incubator.yml +++ b/.github/workflows/deploy-to-incubator.yml @@ -11,7 +11,7 @@ permissions: id-token: write contents: read jobs: - TerraformPlan: + Deploy: runs-on: ubuntu-latest steps: - name: Clone repo @@ -21,7 +21,7 @@ jobs: uses: aws-actions/configure-aws-credentials@v4 with: role-to-assume: arn:aws:iam::035866691871:role/incubator-cicd-home-unite-us - role-session-name: incubator-cicd-people-depot + role-session-name: incubator-cicd-home-unite-us aws-region: us-west-2 - name: Login to Amazon ECR From a25c906090c89fc3936f0bedef8f82568d1f6a3c Mon Sep 17 00:00:00 2001 From: Alex English Date: Sun, 2 Mar 2025 09:40:19 -0800 Subject: [PATCH 04/12] restart ecs service in action --- .github/workflows/deploy-to-incubator.yml | 14 +++++++------- scripts/build-for-incubator.bash | 2 +- scripts/bump-for-incubator.bash | 2 +- 3 files changed, 9 insertions(+), 9 deletions(-) diff --git a/.github/workflows/deploy-to-incubator.yml b/.github/workflows/deploy-to-incubator.yml index ed9b19ef5..859e01372 100644 --- a/.github/workflows/deploy-to-incubator.yml +++ b/.github/workflows/deploy-to-incubator.yml @@ -38,13 +38,13 @@ jobs: docker build -f ./.incubator/app.Dockerfile -t $ECR_REGISTRY/$ECR_REPOSITORY:$IMAGE_TAG . docker push $ECR_REGISTRY/$ECR_REPOSITORY:$IMAGE_TAG - # - name: Redeploy image in ECS - # id: redeploy-service - # env: - # CLUSTER_NAME: incubator-prod - # SERVICE_NAME: home-unite-us-fullstack-${{ inputs.target-host-environment }} - # run: | - # aws ecs update-service --force-new-deployment --service $SERVICE_NAME --cluster $CLUSTER_NAME + - name: Redeploy image in ECS + id: redeploy-service + env: + CLUSTER_NAME: incubator-prod + SERVICE_NAME: home-unite-us-fullstack-${{ inputs.target-host-environment }} + run: | + aws ecs update-service --force-new-deployment --service $SERVICE_NAME --cluster $CLUSTER_NAME diff --git a/scripts/build-for-incubator.bash b/scripts/build-for-incubator.bash index a7d1b897f..8e4128847 100644 --- a/scripts/build-for-incubator.bash +++ b/scripts/build-for-incubator.bash @@ -15,7 +15,7 @@ done; COMMIT_PREFIX="$(git log -n1 --pretty='%H' | head -c10)" TIMESTAMP="$(date +%Y%m%d-%H%M%S)" -ECR_REPO='035866691871.dkr.ecr.us-west-2.amazonaws.com/homeuniteus' +ECR_REPO='035866691871.dkr.ecr.us-west-2.amazonaws.com/home-unite-us-fullstack' IMAGE_URL="${ECR_REPO}:${COMMIT_PREFIX}.${TIMESTAMP}" diff --git a/scripts/bump-for-incubator.bash b/scripts/bump-for-incubator.bash index d1e2e3aab..96a0c2de8 100644 --- a/scripts/bump-for-incubator.bash +++ b/scripts/bump-for-incubator.bash @@ -19,7 +19,7 @@ done; COMMIT_PREFIX="$(git log -n1 --pretty='%H' | head -c10)" TIMESTAMP="$(date +%Y%m%d-%H%M%S)" -ECR_REPO='035866691871.dkr.ecr.us-west-2.amazonaws.com/homeuniteus' +ECR_REPO='035866691871.dkr.ecr.us-west-2.amazonaws.com/home-unite-us-fullstack' IMAGE_URL="${ECR_REPO}:${COMMIT_PREFIX}.${TIMESTAMP}" From 504e8aa79bb80fa07326a911f701cfbc78bd8b83 Mon Sep 17 00:00:00 2001 From: Alex English Date: Sun, 2 Mar 2025 12:00:57 -0800 Subject: [PATCH 05/12] use blank boto client constructor if COGNITO_ACCESS_ID and COGNITO_ACCESS_KEY are not present --- flask-api/openapi_server/app.py | 14 +++++++++----- 1 file changed, 9 insertions(+), 5 deletions(-) diff --git a/flask-api/openapi_server/app.py b/flask-api/openapi_server/app.py index f9f7c3684..cb47c2516 100644 --- a/flask-api/openapi_server/app.py +++ b/flask-api/openapi_server/app.py @@ -52,11 +52,15 @@ def boto_client(self): if self._boto_client: return self._boto_client - self._boto_client = boto3.client('cognito-idp', - region_name=self.config["COGNITO_REGION"], - aws_access_key_id=self.config["COGNITO_ACCESS_ID"], - aws_secret_access_key=self.config["COGNITO_ACCESS_KEY"] - ) + # if this is running in ECS, we need to not set aws_access_key_id and aws_secret_access_key + if (len(self.config["COGNITO_ACCESS_ID"] || "") == 0 or len(self.config["COGNITO_ACCESS_ID"] || "") == 0) + self._boto_client = boto3.client('cognito-idp') + else + self._boto_client = boto3.client('cognito-idp', + region_name=self.config["COGNITO_REGION"], + aws_access_key_id=self.config["COGNITO_ACCESS_ID"], + aws_secret_access_key=self.config["COGNITO_ACCESS_KEY"] + ) return self._boto_client def calc_secret_hash(self, username: str) -> str: From 2c99342837cf69d746ee9c722e63f7f2f4f37ffa Mon Sep 17 00:00:00 2001 From: Alex English Date: Sun, 2 Mar 2025 13:31:18 -0800 Subject: [PATCH 06/12] fix cognito dependency --- backend/app/modules/deps.py | 4 ++++ 1 file changed, 4 insertions(+) diff --git a/backend/app/modules/deps.py b/backend/app/modules/deps.py index 8e2fe0355..3be07c05d 100644 --- a/backend/app/modules/deps.py +++ b/backend/app/modules/deps.py @@ -60,6 +60,10 @@ def db_session(engine: DbEngineDep): DbSessionDep = Annotated[Session, Depends(db_session)] def get_cognito_client(settings: SettingsDep): + # if this is running in ECS, we need to not set aws_access_key_id and aws_secret_access_key + if (len(self.config["COGNITO_ACCESS_ID"] || "") == 0 or len(self.config["COGNITO_ACCESS_ID"] || "") == 0) + return boto3.client('cognito-idp') + cognito_client = boto3.client( "cognito-idp", region_name=settings.COGNITO_REGION, From d56dd3a250ce547357dfe1b7b97c09fef30994ae Mon Sep 17 00:00:00 2001 From: Alex English Date: Sun, 2 Mar 2025 13:41:45 -0800 Subject: [PATCH 07/12] fix env var --- backend/app/modules/deps.py | 3 ++- 1 file changed, 2 insertions(+), 1 deletion(-) diff --git a/backend/app/modules/deps.py b/backend/app/modules/deps.py index 3be07c05d..eb177bb47 100644 --- a/backend/app/modules/deps.py +++ b/backend/app/modules/deps.py @@ -1,3 +1,4 @@ +import os import boto3 import jwt @@ -61,7 +62,7 @@ def db_session(engine: DbEngineDep): def get_cognito_client(settings: SettingsDep): # if this is running in ECS, we need to not set aws_access_key_id and aws_secret_access_key - if (len(self.config["COGNITO_ACCESS_ID"] || "") == 0 or len(self.config["COGNITO_ACCESS_ID"] || "") == 0) + if (len(os.environ["COGNITO_ACCESS_ID"] || "") == 0 or len(os.environ["COGNITO_ACCESS_ID"] || "") == 0) return boto3.client('cognito-idp') cognito_client = boto3.client( From 27865c1b6b31555a0650eb979bf3afc3fec1ca5c Mon Sep 17 00:00:00 2001 From: Alex English Date: Sun, 2 Mar 2025 13:56:02 -0800 Subject: [PATCH 08/12] fix env var --- backend/app/modules/deps.py | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/backend/app/modules/deps.py b/backend/app/modules/deps.py index eb177bb47..5a0aa98dc 100644 --- a/backend/app/modules/deps.py +++ b/backend/app/modules/deps.py @@ -62,7 +62,7 @@ def db_session(engine: DbEngineDep): def get_cognito_client(settings: SettingsDep): # if this is running in ECS, we need to not set aws_access_key_id and aws_secret_access_key - if (len(os.environ["COGNITO_ACCESS_ID"] || "") == 0 or len(os.environ["COGNITO_ACCESS_ID"] || "") == 0) + if len(os.environ["COGNITO_ACCESS_ID"] || "") == 0 or len(os.environ["COGNITO_ACCESS_ID"] || "") == 0: return boto3.client('cognito-idp') cognito_client = boto3.client( From cc8f37291994b376e9993249fa4861e96d474255 Mon Sep 17 00:00:00 2001 From: Alex English Date: Sun, 2 Mar 2025 14:04:11 -0800 Subject: [PATCH 09/12] fix env var --- backend/app/modules/deps.py | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/backend/app/modules/deps.py b/backend/app/modules/deps.py index 5a0aa98dc..18359daf2 100644 --- a/backend/app/modules/deps.py +++ b/backend/app/modules/deps.py @@ -62,7 +62,7 @@ def db_session(engine: DbEngineDep): def get_cognito_client(settings: SettingsDep): # if this is running in ECS, we need to not set aws_access_key_id and aws_secret_access_key - if len(os.environ["COGNITO_ACCESS_ID"] || "") == 0 or len(os.environ["COGNITO_ACCESS_ID"] || "") == 0: + if len(os.environ["COGNITO_ACCESS_ID"]) == 0 or len(os.environ["COGNITO_ACCESS_ID"]) == 0: return boto3.client('cognito-idp') cognito_client = boto3.client( From 07a1b380ca5d9f8dfd50adce84290838786bf308 Mon Sep 17 00:00:00 2001 From: Alex English Date: Sun, 2 Mar 2025 14:06:50 -0800 Subject: [PATCH 10/12] fix env var --- flask-api/openapi_server/app.py | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/flask-api/openapi_server/app.py b/flask-api/openapi_server/app.py index cb47c2516..dbb3e9bcd 100644 --- a/flask-api/openapi_server/app.py +++ b/flask-api/openapi_server/app.py @@ -53,7 +53,7 @@ def boto_client(self): return self._boto_client # if this is running in ECS, we need to not set aws_access_key_id and aws_secret_access_key - if (len(self.config["COGNITO_ACCESS_ID"] || "") == 0 or len(self.config["COGNITO_ACCESS_ID"] || "") == 0) + if len(self.config["COGNITO_ACCESS_ID"]) == 0 or len(self.config["COGNITO_ACCESS_ID"]) == 0: self._boto_client = boto3.client('cognito-idp') else self._boto_client = boto3.client('cognito-idp', From 938b349ad0149b762fb12f403a1b0755aa5bac75 Mon Sep 17 00:00:00 2001 From: Alex English Date: Sun, 30 Aug 2026 12:38:41 -0700 Subject: [PATCH 11/12] remove legacy workflows and update deploy-to-incubator workflow for prod --- .github/workflows/build-deploy-ec2.yml | 125 ---------------------- .github/workflows/deploy-aws-full.yml | 23 ---- .github/workflows/deploy-to-incubator.yml | 1 + 3 files changed, 1 insertion(+), 148 deletions(-) delete mode 100644 .github/workflows/build-deploy-ec2.yml delete mode 100644 .github/workflows/deploy-aws-full.yml diff --git a/.github/workflows/build-deploy-ec2.yml b/.github/workflows/build-deploy-ec2.yml deleted file mode 100644 index f1b5f0477..000000000 --- a/.github/workflows/build-deploy-ec2.yml +++ /dev/null @@ -1,125 +0,0 @@ -name: Build and Deploy to EC2 -# workflow_dispatch means this workflow is manually triggered. -# The user will select the branch or tag from the GitHub UI to run this workflow against. -on: - workflow_dispatch: -jobs: - run-tests: - uses: ./.github/workflows/run-tests-v1.yml - build-api: - runs-on: ubuntu-latest - needs: run-tests - defaults: - run: - shell: bash - working-directory: ./api - outputs: - # sdist is a variable that will contain the filename of the API build package - # It will be used in the deployment job to know which file to deploy. - sdist: ${{ steps.package.outputs.sdist }} - steps: - - uses: actions/checkout@main - with: - fetch-depth: 500 - fetch-tags: true - - name: Set up Python 3.10 - uses: actions/setup-python@v4 - with: - python-version: "3.10" - cache: "pip" - - name: Upgrade pip - run: python -m pip install --upgrade pip - - name: Build API Deployment Package - id: package - run: | - # It is designed that if $SDIST does not exists then this job will fail. - # $SDIST is used to set this workflow's sdist variable for use in the deploy job - python -m pip install build - SDIST=$(python -m build --sdist | perl -n -e '/^Successfully built (.*)\.tar\.gz$/ && print $1') - [ -n "$SDIST" ] && echo "sdist=$SDIST" >> "$GITHUB_OUTPUT" - - name: Archive API Deployment Package - uses: actions/upload-artifact@v3 - with: - name: api - path: api/dist - retention-days: 7 - build-app: - runs-on: ubuntu-latest - needs: run-tests - defaults: - run: - shell: bash - working-directory: ./app - steps: - - uses: actions/checkout@v4 - - name: Use Node.js 20 - uses: actions/setup-node@v4 - with: - node-version: 20 - cache: "npm" - cache-dependency-path: app/package-lock.json - - name: Run npm CI - run: npm ci - - name: Build app - env: - # This environment variable is read by the app during the build - # It is a required variable to set the API url in the app - VITE_HUU_API_BASE_URL: ${{ vars.VITE_HUU_API_BASE_URL }} - run: npm run build - - name: Archive App - uses: actions/upload-artifact@v3 - with: - name: app - path: app/dist - retention-days: 7 - deploy-api-app: - needs: [build-api, build-app] - runs-on: ubuntu-latest - steps: - - name: Download all workflow run artifacts - uses: actions/download-artifact@v4.1.7 - - name: Install SSH key - uses: shimataro/ssh-key-action@v2 - with: - key: ${{ secrets.HUU_EC2_SSH_KEY }} - # The value below is the server's PUBLIC key. It's a required attribute for this action. - known_hosts: homeunite.us ssh-rsa AAAAB3NzaC1yc2EAAAADAQABAAABAQCu/AdtdkNgDuezmkVeENDtC1Mf2erROKDEslMj+RFwuXj5CuLG2PRNTpzebgVlIJwxrq76+QWEFFG4gub2+mq2N+FlQ/if+R+a3Ym7lS3J25usgBliO6Dgp3Oxuq6n3V3/SopXIZ3/p8zGyBOiEjF8NXXy6y/ByfqT61jhZZR4MuMxdsaTbOI8wYfCAkxJTRn7E3U36iZNxgyxl5LCw97AxxiAzzg+f4GmpY7JuNy0EEqAEdRHPs6LBjrmDw6QLkDVS7AEA64yF8cDqDtNdB4Q/SkmJ0AyggU+fkFJ+wq01+mjtBMfjlaMmk+a2KowCIU6L+Mo2E7FnbQ0vKBg4iY3 - - name: rsync over SSH API and App to EC2 - run: | - # upload the api and app directories to the EC2 instance - rsync --mkpath -r app ubuntu@homeunite.us:github-deploy/ - rsync --mkpath -r api ubuntu@homeunite.us:github-deploy/ - # /home/ubuntu/github-deploy/api contains the sdist - # /home/ubuntu/github-deploy/app contains the frontend app source - - name: Configure EC2 - uses: appleboy/ssh-action@v1.0.0 - env: - SDIST: ${{needs.build-api.outputs.sdist}} - with: - host: homeunite.us - username: ubuntu - key: ${{ secrets.HUU_EC2_SSH_KEY }} - script_stop: true - envs: SDIST - script: | - # TODO: Run database migration scripts - cd /home/ubuntu - ./create_archive.bash - - # Update database - - # Deploy API - cd /home/ubuntu/github-deploy/api - source /opt/dev.homeunite.us/dev-huu-env/bin/activate - pip uninstall -y -r <(pip freeze) || echo "Nothing to uninstall" - pip install --upgrade pip - pip install -r <(tar xfO $SDIST.tar.gz $SDIST/requirements.txt) - pip install "$SDIST.tar.gz[prod]" - deactivate - sudo systemctl restart dev-homeuniteus-api.service - rm -rf /home/ubuntu/github-deploy/api/* - - # Deploy front-end app - cd /home/ubuntu/github-deploy/app - sudo rsync -a * /var/www/dev.homeunite.us/html/ - rm -r /home/ubuntu/github-deploy/app/* diff --git a/.github/workflows/deploy-aws-full.yml b/.github/workflows/deploy-aws-full.yml deleted file mode 100644 index 6ccb05110..000000000 --- a/.github/workflows/deploy-aws-full.yml +++ /dev/null @@ -1,23 +0,0 @@ -name: Deploy to AWS -on: - workflow_dispatch: -env: - AWS_REGION : "us-east-2" -permissions: - id-token: write # This is required for requesting the JWT - contents: read # This is required for actions/checkout -jobs: - terraform: - runs-on: ubuntu-latest - steps: - - name: Git clone the repository - uses: actions/checkout@v4 - - name: configure aws credentials - uses: aws-actions/configure-aws-credentials@v3 - with: - role-to-assume: arn:aws:iam::058264103110:role/homeuniteus-tf-user - role-session-name: hackforlarolesession - aws-region: ${{ env.AWS_REGION }} - - name: initialize terraform - run: | - echo "tf init" diff --git a/.github/workflows/deploy-to-incubator.yml b/.github/workflows/deploy-to-incubator.yml index 859e01372..b1c1c7043 100644 --- a/.github/workflows/deploy-to-incubator.yml +++ b/.github/workflows/deploy-to-incubator.yml @@ -7,6 +7,7 @@ on: description: The AWS environment to deploy (dev/test/prod) options: - qa + - prod permissions: id-token: write contents: read From 9bd766d0841ca5d9e87eb4ef6e03a5631f19a45a Mon Sep 17 00:00:00 2001 From: Alex English Date: Sun, 30 Aug 2026 16:22:42 -0700 Subject: [PATCH 12/12] Fix missing colon on else and compare COGNITO_ACCESS_KEY in cognito client guards --- backend/app/modules/deps.py | 2 +- flask-api/openapi_server/app.py | 4 ++-- 2 files changed, 3 insertions(+), 3 deletions(-) diff --git a/backend/app/modules/deps.py b/backend/app/modules/deps.py index 18359daf2..28ff6818d 100644 --- a/backend/app/modules/deps.py +++ b/backend/app/modules/deps.py @@ -62,7 +62,7 @@ def db_session(engine: DbEngineDep): def get_cognito_client(settings: SettingsDep): # if this is running in ECS, we need to not set aws_access_key_id and aws_secret_access_key - if len(os.environ["COGNITO_ACCESS_ID"]) == 0 or len(os.environ["COGNITO_ACCESS_ID"]) == 0: + if len(os.environ["COGNITO_ACCESS_ID"]) == 0 or len(os.environ["COGNITO_ACCESS_KEY"]) == 0: return boto3.client('cognito-idp') cognito_client = boto3.client( diff --git a/flask-api/openapi_server/app.py b/flask-api/openapi_server/app.py index dbb3e9bcd..588cfea4e 100644 --- a/flask-api/openapi_server/app.py +++ b/flask-api/openapi_server/app.py @@ -53,9 +53,9 @@ def boto_client(self): return self._boto_client # if this is running in ECS, we need to not set aws_access_key_id and aws_secret_access_key - if len(self.config["COGNITO_ACCESS_ID"]) == 0 or len(self.config["COGNITO_ACCESS_ID"]) == 0: + if len(self.config["COGNITO_ACCESS_ID"]) == 0 or len(self.config["COGNITO_ACCESS_KEY"]) == 0: self._boto_client = boto3.client('cognito-idp') - else + else: self._boto_client = boto3.client('cognito-idp', region_name=self.config["COGNITO_REGION"], aws_access_key_id=self.config["COGNITO_ACCESS_ID"],